Fenêtres publicitaires

Fermé
akou21 - 4 janv. 2010 à 13:17
akou21 Messages postés 5 Date d'inscription lundi 2 juin 2008 Statut Membre Dernière intervention 30 mars 2010 - 30 mars 2010 à 22:39
Bonjour, merci d'avoir lire mon message et de me répondre s'il vous plais.

mon problème: j'ai le Firefox et internet explorer sur mon ordinateur avec Windows XP, mais en utilisant internet ou non (avec connexion établi bien sur) l'internet explorer s'ouvre seul sur un site que je les recopié son adresse:

( http://ww17.scache.eorezo.com/html/engine/after.htm?&x_src_=UMLCe5lZK%2F9%2FmwJ2D5wRQSC3sKWZ1HuBFMoyN6Jp34ughE6nTP%2BXYHlP9hHUiEVysst1TfHFkQScfefRqqF3z%2FsfSryYDajGqoQWwAj%2BAAPuZ9%2BumdZfVqTfpFfg%2Flv5J4Tt%2FA7C6wDxdR9EuOHztgRHDyWWN7hnBClH53tmTrYthhxvKJbBkY%2FveyexGrHo4QyfSgh9EWQLxsz7JTM8XA%3D%3D ).

j'espère que ça est suffisant en attendant votre réponses.

14 réponses

Utilisateur anonyme
4 janv. 2010 à 14:33
bonjour,
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

- http://images.malwareremoval.com/random/RSIT.exe

! Déconnecte toi et ferme toutes tes applications en cours !

* Double-clique sur RSIT.exe pour le lancer .
* Une première fenêtre s'ouvre avec en titre : Disclaimer of warranty .
* Devant l'option List files/folders created ... , tu choisis 2 months
* Clique ensuite sur Continue pour lancer l'analyse ...
* Laisse faire le scan et ne touche pas au PC ...
* Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).
* Héberge le contenu de log.txt (c'est celui qui apparait à l'écran), ainsi que de info.txt ici.
Clique sur parcourir
Une fois que tu as trouvé les rapports à héberger, clique sur ouvrir
Clique sur Cliquez ici pour déposer le fichier, puis donne le lien
qui apparait comme ceci http:/www.cijoint.fr/cjlink.php?file=cj200911/cijgAdC3Ch.txt

Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit
0
j'utilise "CA Yahoo Antispy" est-ce qu'il faut le désinstaller avant d'utiliser le programme que vous m'avez demander d'installer ou c'est inutile de l'éliminer.
0
Utilisateur anonyme
5 janv. 2010 à 15:31
bonjour
il faudrai essayer de le désactiver le temps des manipulations
0
Le lien de info:

http://www.cijoint.fr/cjlink.php?file=cj201001/cijFnls0te.txt

voila log bloc notes, (log txt):

Logfile of random's system information tool 1.06 (written by random/random)
Run by taha rajil at 2010-01-06 10:02:23
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 24 GB (49%) free of 50 GB
Total RAM: 511 MB (47% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-11-11 173488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2009-09-20 1172280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - c:\program files\real\realplayer\rpbrowserrecordplugin.dll [2009-12-10 329312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31c322dc-5878-452e-a2d8-c4aab9973c9a}]
interdescargas-FR Toolbar - C:\Program Files\interdescargas-FR\tbinte.dll [2009-10-01 2166296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-12-12 1111320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91ebc924-552d-3096-9c5b-0a60b1ae6178}]
flvdirect - C:\WINDOWS\system32\Q_0W7XN3P2E.dll [2009-11-16 1138688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9c96564f-8d9b-867e-0a93-7cf55e751b3d}]
flvdirect - C:\WINDOWS\system32\xysmF7GRw-W.dll [2009-12-25 1159168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-09-02 1107200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-09 263280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-09 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}]
EoBHO Class - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll [2008-11-18 42792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
Hotspot Shield Toolbar - C:\Program Files\Hotspot_Shield\tbHot1.dll [2009-12-23 2166296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-14 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-14 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
Hotspot Shield Class - C:\Program Files\Hotspot Shield\hssie\HssIE.dll [2009-12-25 218160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [2009-09-20 158008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2009-09-20 1172280]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-09-02 1107200]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-09 263280]
{9ec204df-0e48-4c32-816e-2e928a4fd9c2} - WalterShop - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{31c322dc-5878-452e-a2d8-c4aab9973c9a} - interdescargas-FR Toolbar - C:\Program Files\interdescargas-FR\tbinte.dll [2009-10-01 2166296]
{c95a4e8e-816d-4655-8c79-d736da1adb6d} - Hotspot Shield Toolbar - C:\Program Files\Hotspot_Shield\tbHot1.dll [2009-12-23 2166296]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-03 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-03 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-03 455168]
"SiSPower"=SiSPower.dll,ModeAgent []
"DivX Free Codec"=C:\Program Files\DivX Free Codec\Divx Free Update.exe []
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"FrameWorkService"= []
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-08-17 90112]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-12-12 2043160]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-11-10 417792]
"VMSnap3"=C:\WINDOWS\Paizhao.EXE [2007-01-09 49152]
"Domino"=C:\WINDOWS\Recovery.EXE [2007-01-09 49152]
"BigDog303"=C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH) []
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-12-10 198160]
"YSearchProtection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2009-02-23 111856]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-12-14 149280]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"EoEngine"=C:\Program Files\EoRezo\EoEngine.exe [2009-02-23 472872]
"SoftwareHelper"=C:\Documents and Settings\taha rajil\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe [2008-12-09 368224]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"HP Online Support"=C:\WINDOWS\system32\ConSvc.exe [2009-12-12 761110]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]
"FrameWorkService"= []
"Messenger (Yahoo!)"=C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe [2009-11-10 5244216]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-09 39408]
"Search Protection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2009-02-23 111856]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-11-11 3171760]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe

C:\Documents and Settings\taha rajil\Menu Démarrer\Programmes\Démarrage
Notification de cadeaux MSN.lnk - C:\Documents and Settings\taha rajil\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-11-04 11952]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"DisallowRun"=0
"NoFolderOptions"=0
"NoRun"=0
"NoFind"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe"="C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe:*:Enabled:NFSHP2"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10ef3db6-0f04-11de-8947-00e04d0bb012}]
shell\AutoRun\command - D:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a942dc36-779a-11de-8a13-00e04d0bb012}]
shell\AutoRun\command - D:\zngyem.exe
shell\explore\command - D:\zngyem.exe
shell\open\command - D:\zngyem.exe


======List of files/folders created in the last 2 months======

2010-01-06 10:02:25 ----D---- C:\Program Files\trend micro
2010-01-06 10:02:23 ----D---- C:\rsit
2010-01-04 15:44:05 ----D---- C:\Program Files\Common Files
2010-01-04 15:32:29 ----D---- C:\Program Files\Fichiers communs\Scanner
2010-01-01 09:23:47 ----SHD---- C:\Config.Msi
2009-12-31 23:33:47 ----D---- C:\WINDOWS\Reflexive Arcade Games - Action
2009-12-31 23:33:47 ----D---- C:\Program Files\Reflexive Arcade Games - Action
2009-12-31 22:35:19 ----A---- C:\WINDOWS\system32\mKB-kSYr9ug_.exe
2009-12-30 16:55:08 ----A---- C:\WINDOWS\cdplayer.ini
2009-12-30 16:29:17 ----D---- C:\Program Files\Rocket Division Software
2009-12-30 16:25:42 ----D---- C:\Documents and Settings\taha rajil\Application Data\EoRezo
2009-12-30 16:25:39 ----D---- C:\Program Files\EoRezo
2009-12-30 09:27:42 ----D---- C:\Program Files\Microsoft Works
2009-12-30 09:26:38 ----D---- C:\Program Files\Microsoft Visual Studio
2009-12-30 09:25:03 ----D---- C:\Program Files\Microsoft.NET
2009-12-30 09:22:35 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-12-30 09:21:03 ----RHD---- C:\MSOCache
2009-12-30 08:56:26 ----D---- C:\Program Files\Fichiers communs\DESIGNER
2009-12-29 20:45:00 ----D---- C:\WINDOWS\system32\mekanlar
2009-12-29 20:36:48 ----D---- C:\Program Files\WinRAR
2009-12-29 20:21:29 ----D---- C:\Program Files\maktaba chamila
2009-12-29 20:16:52 ----A---- C:\WINDOWS\iun6002.exe
2009-12-29 20:16:42 ----D---- C:\Program Files\المكتبة الشاملة
2009-12-28 22:42:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-12-28 22:41:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2009-12-28 22:40:48 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-12-27 19:34:09 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-12-27 19:33:20 ----D---- C:\WINDOWS\Prefetch
2009-12-27 19:30:19 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-12-27 19:30:05 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-12-27 19:29:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-12-27 19:29:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-27 19:29:28 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-27 19:29:16 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-12-27 19:29:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-12-27 19:28:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-12-27 19:28:32 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-12-27 19:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-12-27 19:28:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-12-27 19:27:46 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2009-12-27 19:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-12-27 19:27:20 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-12-27 19:27:05 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-12-27 19:26:50 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-12-27 19:26:31 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2009-12-27 19:26:14 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-12-27 19:25:57 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-12-27 19:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-12-27 19:25:05 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-12-27 19:24:36 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-12-27 19:24:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2009-12-27 19:23:44 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-12-27 19:23:31 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-12-27 19:22:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-12-27 19:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-12-27 19:22:24 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-12-27 19:21:44 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-12-27 19:21:16 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-12-27 19:20:53 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-12-27 19:20:39 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-12-27 19:20:27 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-12-27 19:20:15 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-12-27 19:19:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-12-27 19:19:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-12-27 19:19:24 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-12-27 19:18:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-12-27 19:18:13 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2009-12-27 19:18:03 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-12-27 19:17:44 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2009-12-27 19:17:29 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-12-27 19:17:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-12-27 19:16:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-12-27 19:16:23 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-12-27 19:16:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-12-27 19:15:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-12-27 19:15:14 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-12-27 19:14:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-12-27 19:14:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-12-27 19:14:31 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-12-27 19:14:15 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-12-27 19:14:02 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-12-27 19:13:46 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-12-27 19:02:00 ----D---- C:\WINDOWS\l2schemas
2009-12-27 19:01:59 ----D---- C:\WINDOWS\system32\fr
2009-12-27 19:01:59 ----D---- C:\WINDOWS\system32\bits
2009-12-27 18:48:53 ----D---- C:\WINDOWS\network diagnostic
2009-12-27 18:37:45 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-12-26 12:28:23 ----D---- C:\WINDOWS\system32\AGEIA
2009-12-26 12:28:23 ----D---- C:\Program Files\AGEIA Technologies
2009-12-25 22:05:22 ----A---- C:\WINDOWS\system32\xysmF7GRw-W.dll
2009-12-25 20:58:50 ----D---- C:\Program Files\Hotspot_Shield
2009-12-25 20:58:49 ----D---- C:\Hotspot Shield
2009-12-25 20:58:44 ----D---- C:\Program Files\Hotspot Shield
2009-12-25 16:56:00 ----D---- C:\Program Files\EA Games
2009-12-25 11:16:41 ----D---- C:\Documents and Settings\All Users\Application Data\DivoGames
2009-12-20 12:35:30 ----HDC---- C:\WINDOWS\ie8
2009-12-20 10:57:35 ----D---- C:\Documents and Settings\taha rajil\Application Data\IDM
2009-12-20 10:57:35 ----D---- C:\Documents and Settings\taha rajil\Application Data\DMCache
2009-12-20 10:57:27 ----D---- C:\Program Files\Internet Download Manager
2009-12-20 05:56:46 ----D---- C:\WINDOWS\Minidump
2009-12-19 18:01:04 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2009-12-19 12:06:35 ----D---- C:\Program Files\Fichiers communs\Oberon Media
2009-12-19 12:06:32 ----D---- C:\Program Files\NGS Games
2009-12-18 19:18:32 ----D---- C:\WINDOWS\system32\LogFiles
2009-12-14 22:57:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961118_0$
2009-12-14 22:56:24 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2009-12-14 21:03:11 ----D---- C:\WINDOWS\Sun
2009-12-14 20:55:51 ----A---- C:\WINDOWS\system32\javaws.exe
2009-12-14 20:55:51 ----A---- C:\WINDOWS\system32\javaw.exe
2009-12-14 20:55:50 ----A---- C:\WINDOWS\system32\java.exe
2009-12-14 20:38:02 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-12-13 08:32:44 ----D---- C:\WINDOWS\system32\XPSViewer
2009-12-13 08:32:37 ----D---- C:\Program Files\MSBuild
2009-12-13 08:32:33 ----D---- C:\WINDOWS\system32\en-US
2009-12-13 08:32:22 ----D---- C:\Program Files\Reference Assemblies
2009-12-13 08:31:02 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-12-13 08:31:00 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-12-13 08:30:58 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-12-13 08:20:01 ----A---- C:\WINDOWS\system32\74W9LaEgxu-_9.exe
2009-12-13 08:19:30 ----D---- C:\Program Files\FLV Direct Player
2009-12-13 08:11:47 ----D---- C:\Program Files\MSXML 6.0
2009-12-12 08:08:10 ----A---- C:\WINDOWS\system32\ConSvc.exe
2009-12-11 23:31:03 ----D---- C:\Program Files\interdescargas-FR
2009-12-11 23:30:28 ----A---- C:\WINDOWS\Instaler Setup Log.txt
2009-12-11 22:52:52 ----D---- C:\Program Files\WalterShop.com
2009-12-11 21:56:56 ----HDC---- C:\WINDOWS\$NtUninstallKB970430_0$
2009-12-11 21:56:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971737_0$
2009-12-11 21:28:30 ----D---- C:\Documents and Settings\taha rajil\Application Data\Mozilla
2009-12-10 21:21:49 ----D---- C:\WINDOWS\SxsCaPendDel
2009-12-10 19:25:59 ----D---- C:\Program Files\Fichiers communs\xing shared
2009-12-10 08:22:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2009-12-10 08:21:48 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2009-12-09 23:41:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2009-12-09 23:39:31 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-12-09 23:39:21 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2009-12-09 22:12:29 ----D---- C:\Documents and Settings\taha rajil\Application Data\Google
2009-12-09 22:06:51 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-12-09 08:29:44 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2009-12-09 08:27:59 ----HDC---- C:\WINDOWS\$NtUninstallKB961503_0$
2009-12-09 08:27:44 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2_0$
2009-12-09 08:26:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2009-12-09 08:26:11 ----HDC---- C:\WINDOWS\$NtUninstallKB971557_0$
2009-12-09 08:25:00 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2009-12-09 08:23:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2009-12-09 08:22:14 ----HDC---- C:\WINDOWS\$NtUninstallKB971633_0$
2009-12-09 08:22:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2009-12-09 08:21:51 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2009-12-09 08:20:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2009-12-09 08:20:02 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2009-12-09 08:19:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-09 08:19:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2009-12-09 08:18:56 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2009-12-09 08:18:03 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2009-12-09 08:14:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2009-12-09 06:24:05 ----HDC---- C:\WINDOWS\$NtUninstallKB969947_0$
2009-12-08 21:57:32 ----D---- C:\Documents and Settings\taha rajil\Application Data\com.adobe.example.avatarAirApplication.199ED43C2CFEB351CD0244628B93195D7C58F98C.1
2009-12-08 19:16:35 ----A---- C:\WINDOWS\system32\vmcoinst_zc0301plh.dll
2009-12-08 19:16:35 ----A---- C:\WINDOWS\system32\DIFxAPI.dll
2009-12-08 19:15:50 ----D---- C:\WINDOWS\EffectResources
2009-12-08 19:15:43 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2009-12-08 19:14:40 ----A---- C:\WINDOWS\recovery.exe
2009-12-08 19:14:35 ----A---- C:\WINDOWS\system32\VM303STI.dll
2009-12-08 19:14:33 ----A---- C:\WINDOWS\Paizhao.exe
2009-12-08 19:14:31 ----A---- C:\WINDOWS\system32\setupfilter.exe
2009-12-08 19:14:30 ----A---- C:\WINDOWS\VM303Cap.exe
2009-12-08 19:14:29 ----A---- C:\WINDOWS\amcap.exe
2009-12-08 19:14:08 ----D---- C:\Program Files\Vimicro
2009-12-08 19:13:28 ----D---- C:\Documents and Settings\taha rajil\Application Data\InstallShield
2009-12-08 14:44:23 ----D---- C:\Documents and Settings\taha rajil\Application Data\Apple Computer
2009-12-08 13:47:55 ----D---- C:\Program Files\QuickTime
2009-12-08 13:47:43 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-12-08 13:47:05 ----D---- C:\Program Files\Fichiers communs\Apple
2009-12-08 13:46:43 ----D---- C:\Program Files\Apple Software Update
2009-12-08 13:46:43 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2009-11-26 16:41:23 ----A---- C:\WINDOWS\system32\idmmbc.dll
2009-11-24 21:12:18 ----D---- C:\Documents and Settings\taha rajil\Application Data\CoSoSys
2009-11-16 12:50:10 ----A---- C:\WINDOWS\system32\Q_0W7XN3P2E.dll
2009-11-14 10:07:16 ----D---- C:\Program Files\Conduit
2009-11-09 17:44:21 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2009-11-09 17:44:10 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-11-09 17:44:01 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-11-09 17:42:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2009-11-09 17:42:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2009-11-09 17:42:08 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-11-09 17:42:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-11-09 17:41:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2009-11-09 17:41:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2009-11-09 17:41:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2009-11-09 17:41:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973354_0$
2009-11-09 17:40:33 ----HDC---- C:\WINDOWS\$NtUninstallKB971486_0$
2009-11-09 17:40:21 ----D---- C:\WINDOWS\ServicePackFiles
2009-11-09 17:40:19 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2009-11-09 17:40:07 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2009-11-09 17:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-11-09 17:39:25 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
2009-11-09 11:07:59 ----D---- C:\Program Files\Microsoft Silverlight
2009-11-09 11:07:39 ----D---- C:\Program Files\Microsoft Office Outlook Connector
2009-11-09 11:03:00 ----RSD---- C:\WINDOWS\assembly
2009-11-09 11:01:31 ----D---- C:\WINDOWS\Microsoft.NET
2009-11-09 11:00:38 ----D---- C:\Program Files\Microsoft Sync Framework
2009-11-09 10:59:37 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-11-09 10:58:19 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2009-11-09 10:57:21 ----D---- C:\Program Files\Microsoft
2009-11-09 10:57:01 ----D---- C:\Program Files\Windows Live SkyDrive
2009-11-09 10:56:34 ----D---- C:\Program Files\Windows Live
2009-11-09 09:54:24 ----D---- C:\Program Files\Fichiers communs\Windows Live
2009-11-09 09:39:26 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$

======List of files/folders modified in the last 2 months======

2010-01-06 10:02:25 ----RD---- C:\Program Files
2010-01-06 09:22:11 ----D---- C:\WINDOWS\Temp
2010-01-06 09:14:17 ----D---- C:\Program Files\Mozilla Firefox
2010-01-05 22:49:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-05 21:33:33 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-05 12:46:51 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-01-05 11:05:20 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-05 08:00:18 ----D---- C:\WINDOWS
2010-01-04 23:05:39 ----D---- C:\Documents and Settings\taha rajil\Application Data\Skype
2010-01-04 22:49:25 ----D---- C:\Documents and Settings\taha rajil\Application Data\skypePM
2010-01-04 18:09:55 ----D---- C:\WINDOWS\system32
2010-01-04 15:47:26 ----D---- C:\Program Files\Yahoo!
2010-01-04 15:42:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-04 15:32:29 ----D---- C:\Program Files\Fichiers communs
2010-01-04 12:12:20 ----HD---- C:\$AVG8.VAULT$
2010-01-04 08:45:28 ----HD---- C:\WINDOWS\inf
2010-01-04 08:45:26 ----D---- C:\Program Files\MSN
2010-01-02 17:13:05 ----D---- C:\Documents and Settings\taha rajil\Application Data\U3
2010-01-01 09:50:19 ----SHD---- C:\WINDOWS\Installer
2010-01-01 09:50:16 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-01-01 09:32:56 ----A---- C:\WINDOWS\WIN.INI
2009-12-31 15:51:08 ----D---- C:\WINDOWS\WinSxS
2009-12-31 13:48:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-12-31 13:48:21 ----RSD---- C:\WINDOWS\Fonts
2009-12-30 22:30:32 ----D---- C:\WINDOWS\system32\CatRoot
2009-12-30 19:30:33 ----SD---- C:\Documents and Settings\taha rajil\Application Data\Microsoft
2009-12-30 09:27:41 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2009-12-30 09:26:48 ----D---- C:\Program Files\Microsoft Office
2009-12-30 09:26:24 ----D---- C:\WINDOWS\ShellNew
2009-12-30 09:25:03 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-12-30 08:46:06 ----D---- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2009-12-30 08:45:06 ----D---- C:\system.sav
2009-12-29 20:12:35 ----A---- C:\WINDOWS\system.ini
2009-12-29 14:47:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-28 22:41:55 ----A---- C:\WINDOWS\imsins.BAK
2009-12-28 22:41:25 ----HD---- C:\WINDOWS\$hf_mig$
2009-12-27 19:34:16 ----A---- C:\WINDOWS\OEWABLog.txt
2009-12-27 19:33:24 ----A---- C:\WINDOWS\setuplog.txt
2009-12-27 19:33:03 ----D---- C:\WINDOWS\system32\wbem
2009-12-27 19:33:03 ----D---- C:\WINDOWS\system32\Setup
2009-12-27 19:33:03 ----D---- C:\WINDOWS\AppPatch
2009-12-27 19:32:57 ----D---- C:\WINDOWS\system32\drivers
2009-12-27 19:28:05 ----D---- C:\Program Files\Outlook Express
2009-12-27 19:19:29 ----D---- C:\WINDOWS\security
2009-12-27 19:14:17 ----D---- C:\Program Files\Messenger
2009-12-27 19:04:24 ----D---- C:\Program Files\Windows Media Player
2009-12-27 19:04:21 ----D---- C:\WINDOWS\Help
2009-12-27 19:03:43 ----D---- C:\WINDOWS\ehome
2009-12-27 19:03:38 ----D---- C:\WINDOWS\system32\inetsrv
2009-12-27 19:03:36 ----D---- C:\WINDOWS\ime
2009-12-27 19:02:14 ----D---- C:\WINDOWS\system32\fr-FR
2009-12-27 19:02:13 ----D---- C:\WINDOWS\system32\usmt
2009-12-27 19:02:02 ----D---- C:\Program Files\Internet Explorer
2009-12-27 19:01:59 ----D---- C:\WINDOWS\PeerNet
2009-12-27 19:01:58 ----D---- C:\Program Files\Movie Maker
2009-12-27 18:53:23 ----D---- C:\WINDOWS\system32\Restore
2009-12-27 18:53:23 ----D---- C:\WINDOWS\system32\npp
2009-12-27 18:53:19 ----D---- C:\WINDOWS\msagent
2009-12-27 18:53:16 ----D---- C:\WINDOWS\srchasst
2009-12-27 18:53:13 ----D---- C:\Program Files\NetMeeting
2009-12-27 18:53:10 ----D---- C:\WINDOWS\system32\Com
2009-12-27 18:53:06 ----D---- C:\Program Files\Windows NT
2009-12-27 18:53:00 ----D---- C:\Program Files\Fichiers communs\System
2009-12-27 18:52:27 ----D---- C:\WINDOWS\system32\oobe
2009-12-27 18:52:23 ----D---- C:\WINDOWS\system
2009-12-27 18:45:29 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-12-25 20:59:55 ----D---- C:\WINDOWS\system32\config
2009-12-25 20:59:37 ----D---- C:\WINDOWS\Registration
2009-12-20 12:57:19 ----D---- C:\WINDOWS\ie8updates
2009-12-20 12:41:13 ----HD---- C:\WINDOWS\msdownld.tmp
2009-12-20 12:37:51 ----D---- C:\WINDOWS\WBEM
2009-12-20 12:37:36 ----D---- C:\WINDOWS\Media
2009-12-20 12:23:44 ----SD---- C:\WINDOWS\Tasks
2009-12-19 13:28:30 ----D---- C:\Program Files\Winamp Toolbar
2009-12-15 10:28:00 ----A---- C:\WINDOWS\avisplitter.INI
2009-12-14 20:55:24 ----D---- C:\Program Files\Java
2009-12-13 08:31:50 ----D---- C:\WINDOWS\system32\spool
2009-12-13 08:22:28 ----D---- C:\WINDOWS\system32\mui
2009-12-12 18:52:15 ----D---- C:\Program Files\MyPlayCity.com
2009-12-12 18:49:26 ----A---- C:\WINDOWS\_MSRSTRT.EXE
2009-12-11 22:26:51 ----D---- C:\Program Files\Google
2009-12-10 21:24:43 ----D---- C:\Documents and Settings\taha rajil\Application Data\Yahoo!
2009-12-10 21:23:48 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-12-10 21:23:40 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-12-10 19:26:36 ----D---- C:\Program Files\Fichiers communs\Real
2009-12-10 19:26:31 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-12-10 19:26:05 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-12-10 19:26:05 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-12-10 19:25:17 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-12-10 07:56:48 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-12-08 19:15:50 ----D---- C:\WINDOWS\twain_32
2009-12-08 19:14:26 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-12-08 19:14:04 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-01 12:06:20 ----A---- C:\WINDOWS\system32\MRT.exe
2009-11-26 08:09:23 ----D---- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2009-11-09 10:59:48 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-11-04 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-11-04 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-11-04 108552]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2006-03-08 12160]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-08-19 3644800]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2009-11-12 32768]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 vmfilter303;vmfilter303; C:\WINDOWS\system32\drivers\vmfilter303.sys [2006-04-25 428160]
R3 ZSMC303;USB PC Camera (Vimicro301 Neptune); C:\WINDOWS\System32\Drivers\usbVM303.sys [2006-12-01 392122]
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2006-03-09 245248]
S3 SiSGR;SiSGR; C:\WINDOWS\system32\DRIVERS\SiSGRp.sys [2006-03-09 245248]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2007-07-03 80552]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2007-07-03 11944]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2007-07-03 106792]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2009-07-22 28592]
S3 tapvpn;TAP VPN Adapter; C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-23 27136]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-11-04 297752]
R2 HotspotShieldService;Hotspot Shield Service; C:\Program Files\Hotspot Shield\bin\openvpnas.exe [2009-11-17 224816]
R2 HssSrv;Hotspot Shield Routing Service; C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe [2009-11-12 331824]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-14 153376]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-09 182768]
S3 HssTrayService;Hotspot Shield Tray Service; C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE [2009-11-17 57640]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------


J'espère que c'est ce que vous avez demander, j'attend votre réponse et merci.
0
Utilisateur anonyme
6 janv. 2010 à 16:19
bonjour
3 infections, dont du vundo et EoRezo qui provoquent l'ouverture de fenêtres publicitaires intempestives
Traitons d'abord EoRezo

EoRezo te propose des logiciels frauduleux qu'il faut éviter de télécharger
On nous demande des informations qui peuvent être utilisées à des fins commerciales
Ces logiciels modifient la page d'accueil, et peuvent faire ramer ton PC


Télécharge AD Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou
https://www.androidworld.fr/

Désactive l'anti-virus

Déconnecte toi et ferme toutes les applications en cours

Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
Double-clique sur l'icône Ad-remover présent sur ton bureau pour le lancer
Au menu principal, sélectionne l'option L, puis appuie sur la touche entrée
Poste le rapport qui apparait à la fin .

( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
.
======= LOGFILE OF AD-REMOVER 1.1.4.6_G | ONLY XP/VISTA/7 =======
.
Updated by C_XX on 05.01.2010 at 18:50
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launch at: 12:58:08, Fri 01/08/2010 | Normal Boot | Option: CLEAN
Executed from: C:\PROGRA~1\AD-REM~1\
Operating system: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Computer Name: TAHA | Current user: taha rajil

.
============== NEUTRALIZED ELEMENT(S) ==============
.

C:\Program Files\EoRezo
C:\DOCUME~1\TAHARA~1\APPLIC~1\EoRezo
C:\DOCUME~1\TAHARA~1\LOCALS~1\Temp\is-SHE0H.tmp\EoRezo

(!) -- Temp files deleted.

.
HKCU\software\appdatalow\HavingFunOnline
HKCU\software\EoRezo
HKCU\software\hotbarsa
HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}
HKCU\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}
HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
HKLM\software\classes\appid\EoRezoBHO.DLL
HKLM\Software\Classes\CLSID\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
HKLM\Software\Classes\CLSID\{20EA9658-6BC3-4599-A87D-6371FE9295FC}
HKLM\Software\Classes\CLSID\{A16AD1E9-F69A-45AF-9462-B1C286708842}
HKLM\Software\Classes\CLSID\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}
HKLM\Software\Classes\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
HKLM\Software\Classes\CLSID\{C9CCBB35-D123-4A31-AFFC-9B2933132116}
HKLM\software\classes\EoRezoBHO.EoBHO
HKLM\software\classes\EoRezoBHO.EoBHO.1
HKLM\Software\Classes\Interface\{819DB72D-1C28-4387-9778-E2FF3DC86F74}
HKLM\Software\Classes\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}
HKLM\Software\Classes\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}
HKLM\Software\Classes\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}
HKLM\software\classes\ShoppingReport.HbAx
HKLM\software\classes\ShoppingReport.HbAx.1
HKLM\software\classes\ShoppingReport.HbInfoBand
HKLM\software\classes\ShoppingReport.HbInfoBand.1
HKLM\software\classes\ShoppingReport.IEButton
HKLM\software\classes\ShoppingReport.IEButton.1
HKLM\software\classes\ShoppingReport.IEButtonA
HKLM\software\classes\ShoppingReport.IEButtonA.1
HKLM\software\classes\ShoppingReport.RprtCtrl
HKLM\software\classes\ShoppingReport.RprtCtrl.1
HKLM\Software\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
HKLM\software\EoRezo
HKLM\Software\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2}
HKLM\Software\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SoftwareHelper
HKLM\software\microsoft\windows\currentversion\uninstall\eoEngine_is1
HKLM\software\microsoft\windows\currentversion\uninstall\SoftwareUpdate_is1
.
============== Added scan ==============
.
.
* Mozilla FireFox Version 3.5.7 [fr] *
.
ProfilePath: cs5cl75r.default (taha rajil)
.
(TAHARA~1, Invalidprefs.js) Browser.download.lastDir, C:\Documents and Settings\taha rajil\Bureau
(TAHARA~1, Invalidprefs.js) Browser.search.defaultenginename, Search
(TAHARA~1, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}
(TAHARA~1, Invalidprefs.js) Browser.search.selectedEngine, Google
(TAHARA~1, Invalidprefs.js) Browser.startup.homepage, hxxp://y.lo.st
(TAHARA~1, Invalidprefs.js) Extensions.enabledItems, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6,{c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.2.14,mozilla_cc@internetdownloadmanager.com:6.3,{31c322dc-5878-452e-a2d8-c4aab9973c9a}:2.5.2.14,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,toolbar@waltershop.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
(TAHARA~1, Invalidprefs.js) Browser.download.lastDir, C:\Documents and Settings\taha rajil\Bureau
(TAHARA~1, Invalidprefs.js) Browser.search.defaultenginename, Search
(TAHARA~1, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}
(TAHARA~1, Invalidprefs.js) Browser.search.selectedEngine, Google
(TAHARA~1, Invalidprefs.js) Browser.startup.homepage, hxxp://www.facebook.com/login.php
(TAHARA~1, Invalidprefs.js) Extensions.enabledItems, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6,{c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.2.14,mozilla_cc@internetdownloadmanager.com:6.3,{31c322dc-5878-452e-a2d8-c4aab9973c9a}:2.5.2.14,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,toolbar@waltershop.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
.
(TAHARA~1, Invalidprefs.js) ERASED - Browser.search.defaultthis.engineName, Hotspot Shield Customized Web Search
(TAHARA~1, Invalidprefs.js) ERASED - Browser.startup.homepage, hxxp://y.lo.st
(TAHARA~1, Invalidprefs.js) ERASED - Browser.search.defaultthis.engineName, Hotspot Shield Customized Web Search
.
(TAHARA~1, prefs.js) Browser.search.defaultenginename, flvdirect
(TAHARA~1, prefs.js) Browser.search.defaulturl, flvdirect
(TAHARA~1, prefs.js) Browser.search.selectedEngine, flvdirect
(TAHARA~1, prefs.js) Browser.startup.homepage, hxxp://www.yahoo.com/
(TAHARA~1, prefs.js) Extensions.enabledItems, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6,{c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.2.14,mozilla_cc@internetdownloadmanager.com:6.3,{31c322dc-5878-452e-a2d8-c4aab9973c9a}:2.5.2.14,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{120692bb-f80a-27dd-efb9-5266726b6de8}:4.6.6.2,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,toolbar@waltershop.com:1.0,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.0.20090922023629,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
(TAHARA~1, prefs.js) Privacy.popups.showBrowserMessage, false
.
(TAHARA~1, user.js) Browser.search.defaultenginename, flvdirect
(TAHARA~1, user.js) Browser.search.defaulturl, flvdirect
(TAHARA~1, user.js) Browser.search.selectedEngine, flvdirect
(TAHARA~1, user.js) Keyword.URL, flvdirect
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Enable Browser Extensions: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Use Search Asst: no
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials, ...) ==============
.
C:\Documents and Settings\taha rajil\Bureau\IDM517__alhandasa+net\Wena4eveR_patch 5.x.x.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\CRACK\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\RegSetup.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\CRACK\NFSHP2.exe
.
===================================
.
8234 Byte(s) - C:\Ad-Report-CLEAN[1].log
.
0 File(s) - C:\DOCUME~1\TAHARA~1\LOCALS~1\Temp
1 File(s) - C:\WINDOWS\Temp
8 File(s) - C:\WINDOWS\Prefetch
.
19 File(s) - C:\PROGRA~1\AD-REM~1\BACKUP
70 File(s) - C:\PROGRA~1\AD-REM~1\QUARANTINE
.
End at: 13:03:43 | Fri 01/08/2010 - CLEAN[1]
.
============== E.O.F ==============
.
0
Utilisateur anonyme
8 janv. 2010 à 14:31
bonjour
C:\Documents and Settings\taha rajil\Bureau\IDM517__alhandasa+net\Wena4eveR_patch 5.x.x.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\CRACK\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\RegSetup.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\CRACK\NFSHP2.exe


lit ceci sur le danger des cracks en cliquant sur ce lien:
https://forum.malekal.com/viewtopic.php?t=893&start=

Télécharge USBFix (de El Desaparecido , C_XX et Chimay8) sur ton bureau
http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe­
ou
https://www.ionos.fr/?affiliate_id=77097

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

# Double clic sur le raccourci UsbFix présent sur ton bureau .

# Sélectionne l'option 1 ( Recherche )

# Laisse travailler l'outil.

# Ensuite poste le rapport UsbFix.txt qui apparaitra.

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

# Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
############################## | UsbFix V6.073 |

User : taha rajil (Administrateurs) # TAHA
Update on 09/01/2010 by El Desaparecido , C_XX & Chimay8
Start at: 20:37:59 | 10-01-2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Pentium(R) 4 CPU 3.06GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local # 48.83 Go (25.47 Go free) # NTFS
E:\ -> Disque fixe local # 48.83 Go (22.6 Go free) # NTFS
F:\ -> Disque fixe local # 55.72 Go (18.58 Go free) # NTFS
J:\ -> Disque amovible
K:\ -> Disque amovible
L:\ -> Disque amovible
M:\ -> Disque amovible
N:\ -> Disque CD-ROM
O:\ -> Disque CD-ROM

############################## | Processus actifs |

C:\WINDOWS\System32\smss.exe 644
C:\WINDOWS\system32\csrss.exe 692
C:\WINDOWS\system32\winlogon.exe 716
C:\WINDOWS\system32\services.exe 760
C:\WINDOWS\system32\lsass.exe 772
C:\WINDOWS\system32\svchost.exe 940
C:\WINDOWS\system32\svchost.exe 988
C:\WINDOWS\System32\svchost.exe 1080
C:\WINDOWS\system32\svchost.exe 1196
C:\WINDOWS\system32\svchost.exe 1240
C:\WINDOWS\system32\spoolsv.exe 1408
C:\WINDOWS\system32\svchost.exe 1612
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 1728
C:\WINDOWS\system32\cisvc.exe 1744
C:\Program Files\Hotspot Shield\bin\openvpnas.exe 1884
C:\WINDOWS\Explorer.EXE 1936
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe 1956
C:\Program Files\Java\jre6\bin\jqs.exe 2012
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 208
C:\WINDOWS\system32\ConSvc.exe 324
C:\WINDOWS\SOUNDMAN.EXE 460
C:\PROGRA~1\AVG\AVG8\avgtray.exe 504
C:\WINDOWS\Paizhao.EXE 556
C:\WINDOWS\Recovery.EXE 580
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe 596
C:\PROGRA~1\AVG\AVG8\avgrsx.exe 604
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe 392
C:\Program Files\Java\jre6\bin\jusched.exe 616
C:\Program Files\Iminent\IMBooster\imbooster.exe 368
C:\PROGRA~1\AVG\AVG8\avgnsx.exe 628
C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe 636
C:\WINDOWS\system32\ctfmon.exe 676
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe 776
C:\WINDOWS\system32\svchost.exe 1064
C:\Program Files\Internet Download Manager\IDMan.exe 1168
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 1212
C:\WINDOWS\system32\sistray.exe 1680
C:\Documents and Settings\taha rajil\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe 2068
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe 2188
C:\WINDOWS\System32\alg.exe 3132
C:\Program Files\Internet Download Manager\IEMonitor.exe 3316
C:\WINDOWS\System32\svchost.exe 3476
C:\Program Files\Hotspot Shield\bin\openvpntray.exe 3632
C:\WINDOWS\system32\cidaemon.exe 1784
C:\Program Files\Skype\Phone\Skype.exe 1052
C:\Program Files\Skype\Plugin Manager\skypePM.exe 204
C:\WINDOWS\system32\wuauclt.exe 3996
C:\WINDOWS\system32\WISPTIS.EXE 5940
C:\Program Files\Mozilla Firefox\firefox.exe 3360
C:\WINDOWS\system32\wbem\wmiprvse.exe 5740

################## | Elements infectieux |

C:\WINDOWS\System32\autorun.inf
C:\khq
E:\khq
F:\khq

################## | Registre |

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FrameWorkService"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "FrameWorkService"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFind"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoRun"

################## | Mountpoints2 |

HKCU\..\..\Explorer\MountPoints2\{10ef3db6-0f04-11de-8947-00e04d0bb012}
Shell\AutoRun\command =D:\LaunchU3.exe -a

HKCU\..\..\Explorer\MountPoints2\{a942dc36-779a-11de-8a13-00e04d0bb012}
Shell\AutoRun\command =D:\zngyem.exe
Shell\explore\Command =D:\zngyem.exe
Shell\open\Command =D:\zngyem.exe

################## | Cracks > Keygens > Serials |

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\CRACK\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\RegSetup.exe"
10/22/2002 02:23 PM |Size 41900 |Crc32 f2517c19 |Md5 473ba82ce8eab6e617987e62d8017568

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\CRACK\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"E:\n\jeux\Aqua bubble 2\Crack\AquaBubble2.exe"
11/28/2008 10:13 PM |Size 252928 |Crc32 45491e50 |Md5 fa83512765642ef05de47b17913fe6ce


################## | ! Fin du rapport # UsbFix V6.073 ! |
0
Utilisateur anonyme
10 janv. 2010 à 21:51
Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

# Double clic sur le raccourci UsbFix présent sur ton bureau

# Sélectionne l'option 2 ( Suppression )

# Ton bureau disparaitra et le pc redémarrera .

# Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

# Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
0
################## | ! Fin du rapport # UsbFix V6.073 ! |
0
Utilisateur anonyme
13 janv. 2010 à 23:10
il est bizarre ce rapport, il n'y a que la fin, il le faudrai en entier
0
pardon mais j'espère que c celui là le rapport en question. et si ce n'est pas le cas, alors explicite moi un peux les étapes précédente et merci.
############################## | UsbFix V6.073 |

User : taha rajil (Administrateurs) # TAHA
Update on 09/01/2010 by El Desaparecido , C_XX & Chimay8
Start at: 21:09:57 | 14-01-2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Pentium(R) 4 CPU 3.06GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

C:\ -> Disque fixe local # 48.83 Go (25.77 Go free) # NTFS
E:\ -> Disque fixe local # 48.83 Go (22.6 Go free) # NTFS
F:\ -> Disque fixe local # 55.72 Go (18.58 Go free) # NTFS
J:\ -> Disque amovible
K:\ -> Disque amovible
L:\ -> Disque amovible
M:\ -> Disque amovible
N:\ -> Disque CD-ROM
O:\ -> Disque CD-ROM

############################## | Processus actifs |

C:\WINDOWS\System32\smss.exe 644
C:\WINDOWS\system32\csrss.exe 692
C:\WINDOWS\system32\winlogon.exe 716
C:\WINDOWS\system32\services.exe 760
C:\WINDOWS\system32\lsass.exe 772
C:\WINDOWS\system32\svchost.exe 940
C:\WINDOWS\system32\svchost.exe 988
C:\WINDOWS\System32\svchost.exe 1080
C:\WINDOWS\system32\svchost.exe 1196
C:\WINDOWS\system32\svchost.exe 1256
C:\WINDOWS\system32\logonui.exe 1324
C:\WINDOWS\system32\spoolsv.exe 1432
C:\WINDOWS\system32\svchost.exe 1580
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 1700
C:\WINDOWS\system32\cisvc.exe 1724
C:\Program Files\Hotspot Shield\bin\openvpnas.exe 1776
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe 1816
C:\Program Files\Java\jre6\bin\jqs.exe 1844
C:\WINDOWS\system32\userinit.exe 1928
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2004
C:\WINDOWS\Explorer.EXE 236
C:\WINDOWS\system32\svchost.exe 316
C:\PROGRA~1\AVG\AVG8\avgrsx.exe 440
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 448
C:\PROGRA~1\AVG\AVG8\avgnsx.exe 464
C:\WINDOWS\system32\wuauclt.exe 672
C:\WINDOWS\System32\alg.exe 2104
C:\WINDOWS\System32\svchost.exe 2552
C:\WINDOWS\system32\wbem\wmiprvse.exe 2688

################## | Elements infectieux |

Supprimé ! C:\Recycler\S-1-5-21-484763869-152049171-725345543-1003
Supprimé ! E:\Recycler\S-1-5-21-484763869-152049171-725345543-1003
Supprimé ! F:\Recycler\S-1-5-21-484763869-152049171-725345543-1003

################## | Registre |


################## | Mountpoints2 |


################## | Listing des fichiers présent |

[01/08/2010 01:03 PM|--a------|8577] C:\Ad-Report-CLEAN[1].log
[02/26/2009 06:18 PM|--a------|0] C:\AUTOEXEC.BAT
[02/27/2009 06:45 PM|--a------|60939848] C:\avg_free_stf_en_8_237a1428.exe
[02/26/2009 06:12 PM|---hs----|212] C:\boot.ini
[09/28/2001 01:00 PM|-rahs----|4952] C:\Bootfont.bin
[02/26/2009 06:18 PM|--a------|0] C:\CONFIG.SYS
[01/08/2010 11:10 AM|--a------|0] C:\dump_dvd.vob
[02/26/2009 06:18 PM|-rahs----|0] C:\IO.SYS
[02/26/2009 06:46 PM|--a------|6] C:\ISACER.ID
[04/21/2008 10:31 PM|--a------|14126401] C:\klcodec390f.exe
[02/26/2009 06:18 PM|-rahs----|0] C:\MSDOS.SYS
[08/03/2004 09:38 PM|-rahs----|47564] C:\NTDETECT.COM
[12/27/2009 06:47 PM|-rahs----|252240] C:\ntldr
[?|?|?] C:\pagefile.sys
[02/27/2009 07:26 PM|--a------|18191016] C:\sdsetup.exe
[01/14/2010 09:12 PM|--a------|3279] C:\UsbFix.txt
[07/23/2009 09:42 PM|--a------|1066] C:\VirtualDJ Local Database v5.xml

################## | Vaccination |

# C:\autorun.inf -> Dossier créé par UsbFix.
# E:\autorun.inf -> Dossier créé par UsbFix.
# F:\autorun.inf -> Dossier créé par UsbFix.

################## | Crack > Keygen > Serial |

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\CRACK\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\RegSetup.exe"
10/22/2002 02:23 PM |Size 41900 |Crc32 f2517c19 |Md5 473ba82ce8eab6e617987e62d8017568

"C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\CRACK\NFSHP2.exe"
10/22/2002 03:11 PM |Size 2973696 |Crc32 73486d12 |Md5 b6aebcaa1b7eff7c2a6ffcfd4d5f874c

"E:\n\jeux\Aqua bubble 2\Crack\AquaBubble2.exe"
11/28/2008 10:13 PM |Size 252928 |Crc32 45491e50 |Md5 fa83512765642ef05de47b17913fe6ce
0
Utilisateur anonyme
14 janv. 2010 à 21:43
Les cracks c'est vecteur d'infections, il faut le supprimer

on va faire un scan généraliste
Télécharge malwarebytes' anti-malware
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
Enregistre le sur le bureau
Double-clique sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation
Si la pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
Il va se mettre à jour une fois faite
Va dans l'onglet recherche
Sélectionne exécuter un examen complet
Clique sur rechercher
Le scan démarre
A la fin de l'analyse, le message s'affiche: L'examen s'est terminé normalement.
Clique sur afficher les résultats pour afficher les objets trouvés
Clique sur OK pour pousuivre
Si des malwares ont été détectés, cliquer sur afficher les résultats
Sélectionne tout (ou laisser coché)
Clique sur supprimer la sélection
Malwarebytes va détruire les fichiers et les clés de registre et en mettre une
copie dans la quarantaine
Malewarebytes va ouvrir le bloc-note et y copier le rapport
Redémarre le PC
Une fois redémarré, double-clique sur Malewarebytes
Va dans l'onglet rapport/log
Clique dessus pour l'afficher une fois affiché, cliquer sur édition en haut du
bloc-note puis sur sélectionner tout
Revient sur édition, puis sur copier et revient sur le forum et dans ta réponse
Clic droit dans le cadre de la réponse et coller
0
pardon, j'ai pas trouver le rapport du malwarebytes mais le problème est résolu est-ce que je continue le travail avec malwarebytes sans le désinstaller. et merci.
0
Utilisateur anonyme
21 janv. 2010 à 22:47
bonsoir
Ouvre Malwarebytes, vas dans l'onglet rapports/log, et tu le trouveras dedans
0
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3569
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

15-01-2010 19:39:02
mbam-log-2010-01-15 (19-39-02).txt

Type de recherche: Examen complet (C:\|E:\|F:\|J:\|K:\|L:\|M:\|N:\|O:\|)
Eléments examinés: 186147
Temps écoulé: 1 hour(s), 19 minute(s), 54 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 10
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 8
Fichier(s) infecté(s): 59

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{ef34404a-747c-81d8-843a-d938e181273d} (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{91ebc924-552d-3096-9c5b-0a60b1ae6178} (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{91ebc924-552d-3096-9c5b-0a60b1ae6178} (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91ebc924-552d-3096-9c5b-0a60b1ae6178} (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\flv direct player (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9c96564f-8d9b-867e-0a93-7cf55e751b3d} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9c96564f-8d9b-867e-0a93-7cf55e751b3d} (Adware.AdRotator) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\FLV Direct Player (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Button (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\ComboBox (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Menu (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window (Adware.BHO.FL) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\Ad-Remover\QUARANTINE\DOCUME~1\TAHARA~1\APPLIC~1\EoRezo\SOFTWA~1\SoftwareUpdate.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\Program Files\Ad-Remover\QUARANTINE\DOCUME~1\TAHARA~1\APPLIC~1\EoRezo\SOFTWA~1\SoftwareUpdateHP.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\Program Files\Ad-Remover\QUARANTINE\PROGRA~1\EoRezo\EoEngine.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\Program Files\Ad-Remover\QUARANTINE\PROGRA~1\EoRezo\EoAdv\EoAdv.dll.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\Program Files\Ad-Remover\QUARANTINE\PROGRA~1\EoRezo\EoAdv\EoRezoBHO.dll.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\-c__P-I-6_f4h.dll (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP164\A0065888.dll (Adware.SmartShopper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP164\A0065890.exe (Trojan.AutoIT) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP167\A0067230.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP167\A0067253.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP167\A0067254.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP167\A0067261.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP167\A0067262.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cftm.exe (Trojan.AutoIT) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Q_0W7XN3P2E.dll (Adware.BHO.FL) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP161\A0064823.exe (Adware.Agent) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP161\A0064824.exe (Adware.Agent) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{CF1190A4-9115-458C-BFAF-438445DD7B8C}\RP161\A0064825.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\downloading.swf (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\dskinliteu.dll (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\FLVPlayer.exe (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\player.dat (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\preload.swf (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\uninstall.exe (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin.xml (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Button\button_default.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Button\button_disable.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Button\button_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Button\button_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Button\button_normal.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonDown.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonHot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonNor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\ComboBox\edit_back.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Menu\menubg.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_arrow.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_check.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Menu\menuitem_select.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_seperator.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\BottomBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\downarrow.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\LeftBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\Logo.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\main.ico (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\RightBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\Program Files\FLV Direct Player\SkinDirectFLV\skin\Window\TitlePattern.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xysmF7GRw-W.dll (Adware.AdRotator) -> Quarantined and deleted successfully.
0
Utilisateur anonyme
23 janv. 2010 à 21:26
bonsoir
étant absente pendant 2 jours j'aimerai voir où il en est ton PC
pourrai tu me refaire un RSIT pour que je puisse voir
0
wallah j'ai pas compri ton message explique moi, est-ce que je refais un autre analyse de malwarebytes ou le rapport n'est pas lisible ou quel est ma prochaine tache. merci
0
Utilisateur anonyme
23 janv. 2010 à 22:19
Wallah ??

refaire un RSIT, pas Malwarebytes
0
pardon monsieur. voila le RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by taha rajil at 2010-01-25 20:55:21
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 25 GB (50%) free of 50 GB
Total RAM: 511 MB (16% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:56:04, on 25-01-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\csrcs.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Paizhao.EXE
C:\WINDOWS\Recovery.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Iminent\IMBooster\imbooster.exe
C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\taha rajil\Mes documents\Téléchargements\RSIT(2).exe
C:\Program Files\trend micro\taha rajil.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.durable.com/recherche
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbinte.dll
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll
F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbinte.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: CHelperBHO - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: IMinent WebBooster - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\IMBooster4Web\Iminent.WebBooster.dll
O2 - BHO: Iminent.LinkToContent - {A6E9BAAF-53CD-4575-967B-2AF710A7D21F} - C:\Program Files\Iminent\IMBooster\Iminent.LinkToContent.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: WalterShop - {9ec204df-0e48-4c32-816e-2e928a4fd9c2} - mscoree.dll (file missing)
O3 - Toolbar: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbinte.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot1.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [DivX Free Codec] C:\Program Files\DivX Free Codec\Divx Free Update.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\Paizhao.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Recovery.EXE
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup
O4 - HKLM\..\Run: [Iminent.Notifier] C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\taha rajil\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKLM\..\Policies\Explorer\Run: [HP Online Support] C:\WINDOWS\system32\ConSvc.exe
O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\taha rajil\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www6.flvdirect.com/?tdfs=0&kw=adult&term=Adult%20Video%20Hosting&term=Group%20Video%20Conferencing&term=Meet%20Singles%20Near%20Me&backfill=0
O15 - Trusted Zone: http://micro.moe.hm
O15 - Trusted Zone: http://axxe.trompizgerbo.com
O15 - ESC Trusted Zone: http://www6.flvdirect.com/?tdfs=0&kw=adult&term=Adult%20Video%20Hosting&term=Group%20Video%20Conferencing&term=Meet%20Singles%20Near%20Me&backfill=0
O15 - ESC Trusted Zone: http://micro.moe.hm
O15 - ESC Trusted Zone: http://axxe.trompizgerbo.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
0
Utilisateur anonyme
25 janv. 2010 à 22:32
pardon monsieur, c'est madame, car je suis une femme

Tu as téléchargé Iminent, un programme qui a infecté ton PC, il ne faut plus le télécharger
Télécharge AD Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou
https://www.androidworld.fr/

Désactive l'anti-virus

Déconnecte toi et ferme toutes les applications en cours

Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
Double-clique sur l'icône Ad-remover présent sur ton bureau pour le lancer
Au menu principal, sélectionne l'option L, puis appuie sur la touche entrée
Poste le rapport qui apparait à la fin .

( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall
0
.
======= LOGFILE OF AD-REMOVER 1.1.4.6_I | ONLY XP/VISTA/7 =======
.
Updated by C_XX on 28.01.2010 at 18:26
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launch at: 11:16:19, Fri 01/29/2010 | Normal Boot | Option: CLEAN
Executed from: C:\Ad-Remover\
Operating system: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Computer Name: TAHA | Current user: taha rajil
.
============== NEUTRALIZED ELEMENT(S) ==============
.

C:\Documents and Settings\taha rajil\temp1.6
C:\WINDOWS\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
C:\Program Files\Mozilla FireFox\extensions\linkcontent@iminent
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\IMBooster
C:\Program Files\Iminent
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Iminent
C:\Documents and Settings\taha rajil\Local Settings\Application Data\Iminent
C:\Windows\Installer\3e3aeb.msi

(!) -- Temp files deleted.

.
HKCU\software\Iminent
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
HKLM\Software\Classes\CLSID\{696E3174-4F6C-4777-7834-654C4A705677}
HKLM\Software\Classes\CLSID\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKLM\Software\Classes\CLSID\{A6E9BAAF-53CD-4575-967B-2AF710A7D21F}
HKLM\software\classes\IminentBHONavigationError.CHelperBHO
HKLM\software\classes\IminentBHONavigationError.CHelperBHO.1
HKLM\software\classes\IminentLinkToContent.LinkToContent
HKLM\software\classes\IminentLinkToContent.LinkToContent.1
HKLM\software\classes\installer\Products\53449B1EE14291541B3C4CDDE93B252A
HKLM\software\classes\installer\Products\C73660D04266C3348A703CD454AD1B48
HKLM\Software\Classes\Interface\{0CA97EEE-C8C4-4B10-A332-10AF1FBEB534}
HKLM\Software\Classes\Interface\{12FB9C3D-0875-4CAA-B3B1-9DCCCE749DE5}
HKLM\Software\Classes\TypeLib\{2C6674DB-EFB5-464A-A715-3E770B9C8A94}
HKLM\Software\Classes\TypeLib\{587D1093-12E0-4B0E-9426-AF9DC5ABB77D}
HKLM\Software\Classes\TypeLib\{77860007-19AE-4C29-B26D-AEA48F3A05C5}
HKLM\software\iAvatars.com
HKLM\software\Iminent
HKLM\software\Loader
HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchTheWeb
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6E9BAAF-53CD-4575-967B-2AF710A7D21F}
HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\53449B1EE14291541B3C4CDDE93B252A
HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\C73660D04266C3348A703CD454AD1B48
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\IMBooster
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Iminent.Notifier
HKLM\software\microsoft\windows\currentversion\uninstall\{0D06637C-6624-433C-A807-C34D45DAB184}
HKLM\software\microsoft\windows\currentversion\uninstall\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
HKLM\software\microsoft\windows\currentversion\uninstall\IMBooster
HKLM\software\microsoft\windows\currentversion\uninstall\SearchTheWeb
.
============== Added scan ==============
.
.
* Mozilla FireFox Version 3.6 [fr] *
.
ProfilePath: cs5cl75r.default (taha rajil)
.
(TAHARA~1, Invalidprefs.js) Browser.download.lastDir, C:\Documents and Settings\taha rajil\Bureau
(TAHARA~1, Invalidprefs.js) Browser.search.defaultenginename, Search
(TAHARA~1, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}
(TAHARA~1, Invalidprefs.js) Browser.search.selectedEngine, Google
(TAHARA~1, Invalidprefs.js) Extensions.enabledItems, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6,{c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.2.14,mozilla_cc@internetdownloadmanager.com:6.3,{31c322dc-5878-452e-a2d8-c4aab9973c9a}:2.5.2.14,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,toolbar@waltershop.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
(TAHARA~1, Invalidprefs.js) Browser.download.lastDir, C:\Documents and Settings\taha rajil\Bureau
(TAHARA~1, Invalidprefs.js) Browser.search.defaultenginename, Search
(TAHARA~1, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}
(TAHARA~1, Invalidprefs.js) Browser.search.selectedEngine, Google
(TAHARA~1, Invalidprefs.js) Browser.startup.homepage, hxxp://www.facebook.com/login.php
(TAHARA~1, Invalidprefs.js) Extensions.enabledItems, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6,{c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.2.14,mozilla_cc@internetdownloadmanager.com:6.3,{31c322dc-5878-452e-a2d8-c4aab9973c9a}:2.5.2.14,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,toolbar@waltershop.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
.
(TAHARA~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\taha rajil\Bureau
(TAHARA~1, prefs.js) Browser.search.defaultenginename, flvdirect
(TAHARA~1, prefs.js) Browser.search.defaulturl, flvdirect
(TAHARA~1, prefs.js) Browser.search.selectedEngine, flvdirect
(TAHARA~1, prefs.js) Browser.startup.homepage, hxxp://fr.msn.com/
(TAHARA~1, prefs.js) Extensions.enabledItems, {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6,{c95a4e8e-816d-4655-8c79-d736da1adb6d}:2.5.6.0,{31c322dc-5878-452e-a2d8-c4aab9973c9a}:2.5.6.0,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{120692bb-f80a-27dd-efb9-5266726b6de8}:4.6.6.2,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.0.20090922023629,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
(TAHARA~1, prefs.js) Privacy.popups.showBrowserMessage, false
.
(TAHARA~1, user.js) Browser.search.defaultenginename, flvdirect
(TAHARA~1, user.js) Browser.search.defaulturl, flvdirect
(TAHARA~1, user.js) Browser.search.selectedEngine, flvdirect
(TAHARA~1, user.js) Keyword.URL, flvdirect
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Enable Browser Extensions: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Use Search Asst: no
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials, ...) ==============
.
C:\Documents and Settings\taha rajil\Bureau\IDM517__alhandasa+net\Wena4eveR_patch 5.x.x.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\CRACK\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\NFSHP2.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\RegSetup.exe
C:\Documents and Settings\taha rajil\Bureau\NFS\CRACK\nfs\CRACK\NFSHP2.exe
.
===================================
.
8577 Byte(s) - C:\Ad-Report-CLEAN[1].log
7985 Byte(s) - C:\Ad-Report-CLEAN[2].log
.
1537 File(s) - C:\DOCUME~1\TAHARA~1\LOCALS~1\Temp
44 File(s) - C:\WINDOWS\Temp
0 File(s) - C:\WINDOWS\Prefetch
.
21 File(s) - C:\Ad-Remover\BACKUP
605 File(s) - C:\Ad-Remover\QUARANTINE
.
End at: 11:21:39 | Fri 01/29/2010 - CLEAN[2]
.
============== E.O.F ==============
.
0
Utilisateur anonyme
29 janv. 2010 à 11:44
bonjour
il faudrai supprimer les toolbars, car elles ne servent à rien et alourdissent la navigation, tu en as une qui est néfaste, c'est la hotspot
Les toolbars, c'est pas obligatoire
Je vais te donner ceci en passant, c'est à lire
https://forum.malekal.com/viewtopic.php?f=45&t=6173
0
Il reste une petite chose, c'est que j'ai supprimé les toolbars sauf celui en question: le Hotspot Shield Toolbar. lorsque je clique sur l'icône "modifier/suprimer" de "ajout/suppression de programmes" du "panneau de configuration" une petite fenêtre qui apparait sous le nom de "Wise Uninstall" et qui porte le texte suivant: ' Could not open INSTALL.LOG file ', avec l'icône ' ok ' sous ce texte. merci d'avance madame.
0
Utilisateur anonyme
29 janv. 2010 à 22:16
essaye de la supprimer avec le logiciel Revo Uninstaller
0
akou21 Messages postés 5 Date d'inscription lundi 2 juin 2008 Statut Membre Dernière intervention 30 mars 2010
30 mars 2010 à 22:39
c'est résolu la problème mais comment peu-je signalée comme résolue
0